nerdexam
Palo_Alto_Networks

PCNSA · Question #49

A network has 10 domain controllers, multiple WAN links, and a network infrastructure with bandwidth needed to support mission-critical applications. Given the scenario, which type of User-ID agent…

The correct answer is A. Windows-based agent on a domain controller. In an infrastructure with remote networks separated by WAN links, the integrated agent is more appropriate for reading remote logs and the Windows-based agent is more appropriate for reading local logs. However, use of the integrated agent is not without cost: It consumes more…

Submitted by weili_xi· Apr 18, 2026Deploy

Question

A network has 10 domain controllers, multiple WAN links, and a network infrastructure with bandwidth needed to support mission-critical applications. Given the scenario, which type of User-ID agent is considered a best practice by Palo Alto Networks?

Options

  • AWindows-based agent on a domain controller
  • BCaptive Portal
  • CCitrix terminal server with adequate data-plane resources
  • DPAN-OS integrated agent

How the community answered

(49 responses)
  • A
    78% (38)
  • B
    6% (3)
  • C
    4% (2)
  • D
    12% (6)

Explanation

In an infrastructure with remote networks separated by WAN links, the integrated agent is more appropriate for reading remote logs and the Windows-based agent is more appropriate for reading local logs. However, use of the integrated agent is not without cost: It consumes more of the firewall’s management plane resources. For this reason, deployment of the Windows agent at remote sites and having them forward the relevant User-ID information to a firewall on a central network often is beneficial.

Topics

#User-ID#Deployment Best Practices#User-ID Agent#Domain Controller Integration

Community Discussion

No community discussion yet for this question.

Full PCNSA Practice